Gentoo: xdrmem_getbytes buffer overflow vulnerability
Summary
- - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200303-29 - - ---------------------------------------------------------------------
- - ---------------------------------------------------------------------
- From advisory:
"The xdrmem_getbytes() function in the XDR library provided by Sun Microsystems contains an integer overflow. Depending on the location and use of the vulnerable xdrmem_getbytes() routine, various conditions may be presented that can permit an attacker to remotely exploit a service using this vulnerable routine."
Read the full advisory at: Privileged Access Management, Cyber Security, and… | BeyondTrust
SOLUTION
It is recommended that all Gentoo Linux users who are running dev-libs/dietlibc upgrade to dietlibc-0.22-r1 as follows:
emerge sync emerge dietlibc emerge clean
- - ------...Read the Full Advisory
Resolution
References
Availability
Concerns
Background